{bc}
indeed

Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid)

CBC/Radio-Canada
Montréal, CAN
Full-time
Senior
Hybrid
Discovered 4 days ago
Third-Party Risk Management (TPRM)Information security risk assessmentISO/IEC 27001NIST SP 800-53 / 800-161COBITITIL
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Third-Party Risk Management (TPRM)Information security risk assessmentISO/IEC 27001
Smart Apply

Full Job Posting

Role overview

CBC/Radio-Canada is seeking a Senior Information Security Analyst, Third-Party Security and Data Breach Expert, to lead its Third-Party Risk Management program.

The role oversees third-party technology risk assessments, reports risk posture to governance and management committees, and advises on governance, risk, and compliance.

Workplace and location

  • This is a hybrid position combining in-office and remote work.
  • The position can be based in Montreal or Toronto.

Key responsibilities

  • Lead the organization-wide Third-Party Risk Management program from process development through operational implementation.
  • Define vendor risk classification frameworks and security assessment questionnaires aligned with industry standards.
  • Review third-party security posture using SOC 2 Type II reports, ISO 27001 certifications, penetration tests, and regulatory attestations.
  • Develop vendor remediation plans, compensating controls, and contractual security requirements.
  • Provide technical leadership during third-party security incidents and data breaches.
  • Maintain third-party risk registers, inventories, periodic reassessments, governance dashboards, KPIs, and KRIs.

Requirements

  • A university degree in computer science, information technology, information security, or a related field is required.
  • At least five years of IT risk governance and TPRM experience, including at least three years focused on information security, is required.
  • Experience with compliance programs, contractual security requirements, and communication with legal and non-technical stakeholders is required.
  • Bilingualism in English and French is essential.

Technical expertise

  • Knowledge of ISO/IEC 27001, 27002, 27005, NIST SP 800-53 or 800-161, COBIT, and ITIL is required.
  • Expertise in cloud and web architecture security, network security, firewalls, IDS/IPS, DNS, web filtering, and encryption is required.
  • Knowledge of database architecture, secure software development, business continuity, disaster recovery, operational resilience, and physical security is required.
  • CISSP, CRISC, CBCP, CISA, CISM, or an equivalent security certification is an asset.

Recruitment checks

Candidates may be subject to skills and knowledge testing.

Candidates advancing in the recruitment process will be asked to complete a background check, including a mandatory criminal record check.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at CBC/Radio-Canada